Agentic Risk & Exposure System
IMPORTANT NOTICE
Please read these Terms of Service carefully before accessing or using the ARES platform. By creating an account, clicking "Request Access," or otherwise accessing the platform, you agree to be bound by these Terms. If you do not agree, you must not use the platform.
In these Terms of Service, the following defined terms shall have the meanings set out below. Unless the context otherwise requires, references to the singular include the plural and vice versa.
2.1 These Terms of Service constitute a legally binding agreement between the Customer and SXGuard. By accessing or using the ARES Platform in any manner — including but not limited to submitting an account registration, clicking "Request Access," or making any API call — the Customer and each Authorized User unconditionally accept these Terms.
2.2 If the Customer is accepting these Terms on behalf of a legal entity, the individual accepting represents and warrants that they have full legal authority to bind that entity to this Agreement. If such authority does not exist, the individual must not use the Platform.
2.3 SXGuard reserves the right to modify these Terms at any time. Material modifications will be communicated via email to the registered account address or via an in-platform notification no less than thirty (30) days prior to the modification taking effect. Continued use of the Platform after the effective date of any modification constitutes acceptance of the revised Terms.
2.4 If any conflict exists between these Terms and a separately executed Order Form or Enterprise Agreement, the terms of the Order Form or Enterprise Agreement shall prevail to the extent of the conflict.
To be eligible to register for and use the ARES Platform, the Customer must:
Customers must complete the account registration process by providing accurate, complete, and current information, including full legal name, business name, business country, business email address, business phone number, and company website. The Customer is responsible for maintaining the accuracy of all registration information and must promptly update any information that becomes incorrect or incomplete.
The Customer is solely responsible for:
SXGuard shall not be liable for any loss, damage, or liability arising from the Customer's failure to comply with these account security obligations.
Account access is subject to SXGuard's review and approval. SXGuard reserves the right, in its sole discretion, to approve or decline any account registration request, including on the basis of the Customer's intended use case, industry classification, geographic location, or compliance with applicable law.
ARES is offered under subscription tiers as specified in the applicable Order Form. Specific features, usage limits, scan quotas, number of Authorized Users, and support entitlements associated with each tier are set out in the applicable Order Form or SXGuard's then-current pricing documentation.
5.2.1 All Fees are as specified in the applicable Order Form. SXGuard reserves the right to update its pricing upon no less than sixty (60) days' written notice to the Customer, which updated pricing shall apply at the commencement of the next Subscription Term renewal.
5.2.2 Unless otherwise specified in the Order Form, all subscription Fees are invoiced annually in advance. Usage-based fees, where applicable, are invoiced monthly in arrears based on actual usage reported by the Platform.
5.2.3 All Fees are stated exclusive of applicable taxes, including VAT, GST, withholding taxes, or any other tax or governmental charge. Where SXGuard is required by law to collect such taxes, they will be added to the invoice at the applicable rate.
5.3.1 Payment is due within thirty (30) days of the invoice date, unless otherwise specified in the Order Form.
5.3.2 SXGuard accepts payment by bank transfer, credit card, or such other methods as notified by SXGuard from time to time. All payments must be made in the currency specified in the Order Form.
5.3.3 In the event of late payment, SXGuard reserves the right to: (i) charge interest on the overdue amount at the rate of one and a half percent (1.5%) per month or the maximum rate permitted by applicable law, whichever is lower; and (ii) suspend access to the Platform upon seven (7) days' written notice if payment is not received within thirty (30) days of the payment due date.
If the Customer disputes any invoice in good faith, the Customer must notify SXGuard in writing within fifteen (15) days of the invoice date, setting out the nature of the dispute and the amount contested. The parties shall work in good faith to resolve any such dispute within thirty (30) days of the dispute notice. Undisputed amounts remain payable in accordance with standard payment terms.
Except as expressly required by applicable law or as set out in Section 14 (Termination), all Fees paid are non-refundable. SXGuard does not provide credits or refunds for partial use, early cancellation outside the agreed Subscription Term, or unused scan quotas.
As between the parties, the Customer retains all right, title, and interest in and to Customer Data. SXGuard claims no ownership over Customer Data. The Customer grants SXGuard a limited, non-exclusive license to process Customer Data solely to the extent necessary to provide the Platform and associated services to the Customer during the Subscription Term.
SXGuard processes personal data in accordance with its Privacy Policy, which is published separately at www.sxguard.com/privacy and is incorporated by reference into this Agreement. To the extent that the Customer provides SXGuard with personal data as part of using the Platform, SXGuard acts as a data processor and the Customer acts as the data controller. SXGuard will process such data only on the Customer's documented instructions and in compliance with applicable data protection legislation, including the Swiss Federal Act on Data Protection (nFADP) and, where applicable, the European Union General Data Protection Regulation (GDPR).
The Customer represents and warrants that it has obtained and will maintain all rights, consents, permissions, and other lawful bases required to collect, process, and transfer any personal data to SXGuard and to authorize SXGuard's processing of such data in connection with the Services. The Customer is solely responsible for complying with all applicable data protection and privacy laws relating to its use of the Platform and the personal data it submits. The Customer shall indemnify and hold harmless SXGuard from any claims, damages, fines, penalties, or liabilities arising from the Customer's breach of its obligations under this Section or applicable data protection laws.
Customer Data is hosted on infrastructure within the geographic region selected by the Customer during onboarding, subject to the available deployment options. For Customers electing the Enterprise On-Premise (Air-Gapped) deployment option, all Customer Data remains exclusively within the Customer's own infrastructure.
SXGuard maintains reasonable and industry-appropriate technical and organizational security measures designed to protect Customer Data against unauthorized access, disclosure, alteration, or destruction. These measures include, but are not limited to: encrypted data transmission (TLS 1.2 or higher), role-based access controls, sandboxed execution environments for scan workers, audit logging, and regular security assessments of the Platform infrastructure.
In the event of a confirmed security incident affecting Customer Data, SXGuard will notify the Customer without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the incident. The notification will include a description of the nature of the incident, the categories and approximate number of data records affected, the likely consequences, and the measures taken or proposed to address the incident.
The Customer acknowledges that vulnerability scan data generated by ARES — including discovered vulnerabilities, exploitable attack paths, and proof-of-concept evidence — constitutes sensitive security information. The Customer is solely responsible for implementing appropriate access controls, handling procedures, and distribution policies for all Scan outputs and reports generated through the Platform.
SXGuard and its licensors retain all right, title, and interest in and to the ARES Platform, including all underlying software, AI models, algorithms, Agent Brain logic, Orchestrator architecture, user interface designs, trademarks, trade names (including "ARES," "SXGuard," and associated marks), Documentation, and all Intellectual Property Rights therein. Nothing in this Agreement transfers ownership of any SXGuard Intellectual Property to the Customer.
The Customer retains all Intellectual Property Rights in Customer Data and in any pre-existing Customer materials. The Customer grants SXGuard no rights in Customer Data beyond the limited processing license set out in Section 6.1.
If the Customer or any Authorized User provides SXGuard with suggestions, ideas, enhancement requests, or other feedback regarding the Platform ("Feedback"), the Customer grants SXGuard a perpetual, irrevocable, royalty-free, worldwide license to use, incorporate, and commercialize such Feedback without restriction or obligation to the Customer.
No license or right is granted under this Agreement by implication, estoppel, or otherwise. Any rights not expressly granted herein are reserved by SXGuard.
Each party agrees to: (i) hold the other party's Confidential Information in strict confidence; (ii) use the other party's Confidential Information solely for the purposes of this Agreement; and (iii) disclose the other party's Confidential Information only to those employees, contractors, and professional advisors who have a legitimate need to know and who are bound by confidentiality obligations no less protective than those set out herein.
Confidentiality obligations do not apply to information that: (i) is or becomes publicly available through no breach of this Agreement; (ii) was already known to the receiving party prior to disclosure; (iii) is independently developed by the receiving party without reference to the Confidential Information; or (iv) is required to be disclosed by applicable law, regulation, or court order, provided that the receiving party gives the disclosing party prompt written notice and cooperates in any effort to limit or resist disclosure.
Confidentiality obligations survive the termination or expiry of this Agreement for a period of five (5) years, except in respect of trade secrets, which shall be protected for as long as they remain trade secrets under applicable law.
Each party represents and warrants that: (i) it has the full legal power and authority to enter into this Agreement; (ii) this Agreement constitutes a valid and binding obligation enforceable against it; and (iii) its execution and performance of this Agreement does not violate any applicable law, regulation, or agreement to which it is a party.
The Customer additionally represents, warrants, and undertakes that:
SXGuard warrants that, during the Subscription Term, the Platform will perform materially in accordance with the Documentation. If the Customer reports a material non-conformance and SXGuard is unable to remedy it within a commercially reasonable time, the Customer's sole and exclusive remedy is to terminate the Agreement in accordance with Section 14 and receive a prorated refund of prepaid Fees for the unused portion of the Subscription Term.
EXCEPT AS EXPRESSLY SET OUT IN SECTION 9.3, THE ARES PLATFORM IS PROVIDED "AS IS" AND "AS AVAILABLE." TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, SXGUARD EXPRESSLY DISCLAIMS ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. SXGUARD DOES NOT WARRANT THAT THE PLATFORM WILL BE UNINTERRUPTED, ERROR-FREE, OR COMPLETELY SECURE, OR THAT ALL VULNERABILITIES IN A TARGET ENVIRONMENT WILL BE IDENTIFIED BY THE PLATFORM.
THE CUSTOMER ACKNOWLEDGES THAT CERTAIN FEATURES OF THE PLATFORM UTILIZE ARTIFICIAL INTELLIGENCE, MACHINE LEARNING, AND AUTOMATED ANALYSIS. ANY OUTPUTS, FINDINGS, RECOMMENDATIONS, REPORTS, OR OTHER RESULTS GENERATED BY THE PLATFORM ARE AUTOMATED, PROBABILISTIC IN NATURE, AND MAY BE INACCURATE, INCOMPLETE, OUTDATED, OR UNSUITABLE FOR A PARTICULAR USE CASE. SUCH OUTPUTS ARE PROVIDED FOR INFORMATIONAL PURPOSES ONLY AND SHOULD NOT BE RELIED UPON AS THE SOLE BASIS FOR SECURITY, COMPLIANCE, OPERATIONAL, LEGAL, OR BUSINESS DECISIONS. THE CUSTOMER IS RESPONSIBLE FOR INDEPENDENTLY REVIEWING, VALIDATING, AND VERIFYING ALL OUTPUTS BEFORE ACTING UPON THEM.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER PARTY SHALL BE LIABLE TO THE OTHER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES ARISING OUT OF OR RELATED TO THIS AGREEMENT OR THE USE OF THE PLATFORM, INCLUDING BUT NOT LIMITED TO LOSS OF REVENUE, LOSS OF PROFITS, LOSS OF BUSINESS, LOSS OF DATA, LOSS OF GOODWILL, OR BUSINESS INTERRUPTION, EVEN IF SUCH PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, SXGUARD'S TOTAL AGGREGATE LIABILITY TO THE CUSTOMER ARISING OUT OF OR IN CONNECTION WITH THIS AGREEMENT, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), BREACH OF STATUTORY DUTY, OR OTHERWISE, SHALL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY THE CUSTOMER IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
Nothing in this Agreement limits or excludes either party's liability for: (i) death or personal injury caused by negligence; (ii) fraud or fraudulent misrepresentation; (iii) any liability that cannot be excluded or limited under applicable law. Customer liability for Malicious Use or unauthorized use of the Platform is not subject to any cap.
The Customer shall indemnify, defend, and hold harmless SXGuard and its officers, directors, employees, and agents from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable legal fees) arising out of or relating to: (i) the Customer's use of the Platform in violation of these Terms; (ii) any Scan or offensive operation conducted by the Customer against an unauthorized target; (iii) any breach by the Customer of applicable law; or (iv) any claim by a third party arising from Customer Data or the Customer's actions in connection with the Platform.
SXGuard will use commercially reasonable efforts to maintain Platform availability of ninety-nine point five percent (99.5%) per calendar month for Customers on paid subscription tiers, calculated excluding scheduled maintenance windows and circumstances beyond SXGuard's reasonable control.
SXGuard reserves the right to perform scheduled maintenance that may result in temporary Platform unavailability. SXGuard will provide at least forty-eight (48) hours' advance notice of scheduled maintenance windows via email or in-platform notification, except in the case of emergency maintenance required to address critical security vulnerabilities or infrastructure failures.
SXGuard provides technical support services in accordance with the support tier associated with the Customer's subscription, as set out in the Order Form or Documentation. Standard support is provided via email at support@sxguard.com during SXGuard's business hours (Monday to Friday, 09:00–18:00 Central European Time, excluding Swiss public holidays). Enterprise support options, including priority response times and dedicated account management, are available under qualifying subscription tiers.
SXGuard reserves the right to modify, enhance, deprecate, or discontinue Platform features at any time. Where the discontinuation of a material feature would materially impair the Customer's use of the Platform, SXGuard will provide no less than ninety (90) days' advance written notice.
The ARES Platform's Agent Brain is model-agnostic and may interface with third-party AI reasoning services including OpenAI GPT-4, Google Vertex AI, and Anthropic Claude, as well as self-hosted open-source models for air-gapped deployments. The Customer acknowledges that the performance and availability of the Platform's AI capabilities may be affected by the operational status of these third-party model providers. SXGuard is not responsible for any service degradation attributable to third-party AI model providers.
The Platform orchestrates a range of third-party security tools, including Nessus, Nuclei, Nmap, Metasploit, and Kali Linux tooling. These tools are subject to their respective third-party licenses. The Customer acknowledges that the use of these tools through the Platform remains subject to applicable law and the authorization requirements set out in Section 4.
References to third-party products, services, or providers within the Platform or Documentation do not constitute an endorsement or warranty by SXGuard with respect to such third parties. The Customer is solely responsible for independently evaluating any third-party services that interact with the Platform.
The Customer is solely responsible for ensuring that its use of the ARES Platform complies with all applicable laws and regulations in each jurisdiction where the Platform is used, including laws governing cybersecurity, penetration testing, unauthorized computer access, data protection, and the export or re-export of security software or technology.
The ARES Platform may be subject to export control and trade sanctions laws of Switzerland, the European Union, and other applicable jurisdictions. The Customer must not access, use, export, re-export, transfer, or otherwise make the Platform available in violation of any applicable export control laws, including any sanctions administered by SECO (Switzerland), OFAC (United States), or equivalent bodies. The Customer represents and warrants that neither the Customer nor any Authorized User is: (i) located in a country subject to a comprehensive trade embargo; or (ii) identified on any governmental denied-party or sanctions list.
The Customer acknowledges that offensive security software constitutes dual-use technology and may be subject to additional regulatory requirements in certain jurisdictions. The Customer assumes full responsibility for obtaining any required licenses, permits, or regulatory approvals prior to using the Platform in any jurisdiction that imposes restrictions on such technology.
This Agreement commences on the date the Customer first accesses the Platform and continues for the duration of the Subscription Term specified in the Order Form, unless earlier terminated in accordance with this Section 14. Unless otherwise specified, subscription terms automatically renew for successive periods equal to the initial term, subject to either party providing written notice of non-renewal no less than thirty (30) days prior to the end of the then-current term.
Either party may terminate this Agreement immediately upon written notice if the other party: (i) materially breaches this Agreement and fails to cure such breach within thirty (30) days of written notice specifying the breach; (ii) becomes insolvent, makes an assignment for the benefit of creditors, or is subject to insolvency or bankruptcy proceedings that are not dismissed within sixty (60) days; or (iii) ceases to operate as a going concern.
SXGuard may suspend access to the Platform immediately and terminate this Agreement without notice if SXGuard reasonably determines that the Customer: (i) is engaged in Malicious Use; (ii) has conducted or is conducting unauthorized security testing of any system or network; (iii) is in material breach of Section 4 (Acceptable Use); or (iv) poses an immediate security risk to SXGuard's infrastructure or other customers.
Upon termination or expiration of this Agreement: (i) all licenses granted under this Agreement immediately terminate; (ii) the Customer must immediately cease all use of the Platform; (iii) each party must, upon written request, return or destroy the other party's Confidential Information; and (iv) all accrued payment obligations remain due and payable. SXGuard will make Customer Data available for export for thirty (30) days following termination, after which SXGuard may permanently delete Customer Data from its systems.
The following Sections survive termination or expiration of this Agreement: Section 1 (Definitions), Section 7 (Intellectual Property Rights), Section 8 (Confidentiality), Section 9.4 (Disclaimer), Section 10 (Limitation of Liability), Section 14.4 (Effects of Termination), Section 15 (Governing Law and Dispute Resolution), and any other provision that by its nature should survive.
This Agreement and any dispute or claim arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims) shall be governed by and construed in accordance with the laws of Switzerland, excluding its conflict-of-law provisions. The United Nations Convention on Contracts for the International Sale of Goods (CISG) shall not apply to this Agreement.
The parties irrevocably submit to the exclusive jurisdiction of the courts of the Canton of Zug, Switzerland, for the resolution of any disputes arising out of or in connection with this Agreement, subject to the arbitration clause in Section 15.3.
Notwithstanding Section 15.2, any dispute, controversy, or claim arising out of or relating to this Agreement, or the breach, termination, or invalidity thereof, that involves amounts in excess of CHF 100,000 shall be finally settled by arbitration administered under the Swiss Rules of International Arbitration of the Swiss Chambers' Arbitration Institution (SCAI). The seat of arbitration shall be Zug, Switzerland. The language of the proceedings shall be English. The number of arbitrators shall be one (1), unless either party requests a panel of three (3). The arbitral award shall be final and binding.
Notwithstanding any other provision of this Agreement, SXGuard reserves the right to seek immediate injunctive or other equitable relief in any court of competent jurisdiction to prevent or restrain any breach or threatened breach of Section 4 (Acceptable Use), Section 7 (Intellectual Property), or Section 8 (Confidentiality) without the requirement to post bond.
This Agreement, together with all applicable Order Forms and any documents expressly incorporated by reference, constitutes the entire agreement between the parties with respect to its subject matter and supersedes all prior negotiations, representations, warranties, agreements, and understandings, whether written or oral, relating to such subject matter.
Except as expressly provided in Section 2.3, no amendment to this Agreement shall be valid unless made in writing and signed by authorized representatives of both parties.
No failure or delay by either party in exercising any right, power, or privilege under this Agreement shall constitute a waiver of that right, power, or privilege. No single or partial exercise of any right, power, or privilege shall preclude any other or further exercise thereof.
If any provision of this Agreement is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction, that provision shall be modified to the minimum extent necessary to make it enforceable, or if modification is not possible, shall be severed from the Agreement, and the remaining provisions shall continue in full force and effect.
The Customer may not assign or transfer this Agreement, or any rights or obligations under it, without SXGuard's prior written consent. SXGuard may freely assign this Agreement to an affiliate or in connection with a merger, acquisition, or sale of all or substantially all of its assets, without the Customer's consent, provided that the assignee assumes all obligations under this Agreement.
Neither party shall be in breach of this Agreement or liable for any delay or failure in performance resulting from causes beyond that party's reasonable control, including acts of God, war, terrorism, pandemic, governmental action, cyberattacks against critical infrastructure, or failure of third-party telecommunications or internet services, provided that the affected party gives prompt written notice and uses reasonable efforts to minimize the impact.
All legal notices under this Agreement must be in writing and delivered by email with confirmed receipt, or by certified mail or internationally recognized courier to: SXGuard: legal@sxguard.com, with a copy to SX Capital AG, Gubelstrasse 24, Zug 6300, Switzerland. Customer: the primary email address and mailing address provided during account registration, or such other address as notified in writing.
The parties are independent contractors. Nothing in this Agreement creates or implies any agency, partnership, joint venture, employment, or fiduciary relationship between the parties. Neither party has authority to bind the other.
This Agreement may be executed in counterparts, each of which shall be deemed an original. Electronic signatures and click-through acceptance shall be legally binding and equivalent to handwritten signatures.
This Agreement has been drafted in English. In the event of any conflict between an English version and a translated version of this Agreement, the English version shall prevail.
For general enquiries, support, or account matters:
For legal notices, data protection matters, and compliance enquiries:
Registered office: SX Capital AG, Gubelstrasse 24, Zug 6300, Switzerland.